Cisco Support Community
Community Member

Pix 525 - AS400 TN5250 Sign On Screen disconnect and session problems

I did install last week a PIX 525 in our company. We use AS400 TN 5250 as our main cpu system. Now we have a problem with our AS400 users which have the Sign On screen disconnected after about 1 hour of no activity and the problem that at the AS400 site the session is locked and at the PC site the session did disconnect. When we try to sign in in the Sign On screen of our AS400 we are running out of ports and the connection is no more established.

Does the PIX close sessions after a period of no data transfer?

Our emulator Client Express needs ports 23, 449, 8470, 8475 and 8476 and there is a polling dialog every 2 min.

The AS400 users on the inside interface doesn't have the problem.

What can be the reason ? Best Regards

Cisco Employee

Re: Pix 525 - AS400 TN5250 Sign On Screen disconnect and session

The PIX will definately close down a TCP connection after 1 hour of inactivity by default. You can change this behaviour with the following command:

> timeout conn 03:00:00

This will set the connection timeout to 3 hours. See

Note that the xlate timeout *should* be higher than the conn timeout, so if you increase the conn timeout, you might need to change the xlate timeout also (this defaults to 3 hours).

CreatePlease to create content